the cio's iot attention points on enterprise architecture ... · •it risk aspects –the...

37
#IoTBuild Luc Verhelst Leading Digital and ISACA certified Risk Adviser CIO at Metallo Group The CIO's IoT attention points on Enterprise Architecture and IT Risk: An effective approach when going digital and integrating the world of IT and OT

Upload: others

Post on 17-Mar-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Luc Verhelst

Leading Digital and ISACA certified Risk Adviser

CIO at Metallo Group

The CIO's IoT attention points on Enterprise Architecture and IT Risk:

An effective approach when going digital and integrating the world of IT and OT

Page 2: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

2

Page 3: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk Adviser .

Luc is currently holding the position as CIO for Metallo group.

Before that he was CIO of the EMA, the European Medicines Agency, based in London, responsible for the supervision of medicines inside Europe.

Previously Luc held different leading CIO roles in leading companies in finance, media, healthcare and logistics.

Luc is also the honorary chairman of MIT-Club, leading Belgian CIO community exchanging valuable CIO knowledge and experiences.

Luc is ISACA certified (CGEIT) and specialised inDigital Strategies with focus on IT governance, Architecture and specifically the IT Risk domain.

BIO: Luc Verhelst

Page 4: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

4

Page 5: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

54%

54%

Page 6: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 7: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 8: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

8

Page 9: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 10: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

In the Industry 4.0 era the world of OT and IT are coming together

Page 11: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 12: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 13: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 14: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 15: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 16: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Page 17: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Data is your most important resource

Page 18: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

The Challenge: The Amount of Data

Page 19: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

19

Page 20: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Accenture 20

Many models circulate, from smaller players to the Big Ones

Page 21: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild3 mei 2016 21

PWC

Page 22: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild3 mei 2016

22

The McKinsey Digital Compass

The McKinsey Digital Compass

Page 23: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Bain & Company

Page 24: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild3 mei 2016 24

Often focused on prototyping, measuring and demonstrating value

Accenture

Page 25: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

25

Page 26: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Enterprise Architecture Framework

Business

Application Architecture

Technical Architecture

Infrastructure Architecture

Data

Risk

Pro

ject

Mgm

t

Page 27: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

The primary obstacle to effective organizational change is cultural.

Well-implemented processes are the product of a broad, multidimensional strategy, led by process owners.

Management must be prepared to adopt a “virtual” matrix organization.

Aligning a traditional, hierarchical organization along process lines requires more than modifying an organization chart.

It is a way of institutionalizing new working relationships across lateral organizational boundaries.

Process ownership is a role that must be filled by an individual or team to oversee the crossfunctionaleffectiveness of the process.

Page 28: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Not a lot of POC’s really become successfullWho do most IoT projects fail?• People & culture

• Poor collaboration between IT, OT and Business

• Culture that focuses too much on Technology

• Lack of Expertise

• Process – going it alone• What looks good on paper proves to be too difficult

• Tie success with the Business• Go with hard numbers, go for ROI within 1-2 years

• Provide easy systems, “operational centric”

• Get Value from Data and

• From the People…

Page 29: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

29

Page 30: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

IT’s all about Processes, Data and Architecture

Page 31: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

• The global vision drives our enterprise architecture, which processes touch which data?

• In our vision OT data (eg PLC) and IT data (MES, ERP) are both to be considered as information, preferably combined

How do we manage, manipulate & secure

the data in our applications and on our

servers?

What type of data can/should we have or

provide/publish?

How can we get maximal value out of this

data?

31

A global vision on Information Management

Page 32: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild32

BIREPORTING

Network

One Enterprise Architectue:

• Application architecure• Data architecture (common

definitions, all aligned)• Security architecture• Infrastracture architecure

(common network, datacenter, servers)

Application architecturebased on ISA95

Datacenter and servers

Electricity

The ISA95 view on application architecture

Page 33: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Agenda• IIoT and Industry 4.0, where suddenly does this Fuss come from?

• But why should the CIO embrace going Digital?

• The Industry 4.0 Frameworks and Methodologies

• The Project Failure and Enterprise Architecture Challenges

• IT’s all about the Data: Architecture and Applications

• IT Risk aspects – the forgotten Challenge?

• Wrap-up / Q&A

33

Page 34: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Overall IT security concept influenced by many different business inputs

34

Page 35: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

A possible IT security framework

35

Page 36: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

IT security roadmap implemented over time

Phase 1Foundation

Phase 2Growth

Phase 3FinalisePreparation phase

Start NOW InitialiseAddress vulnerabilitiesSecurity PolicyInformation classificationOther initiatives Extended Policy

Initiative NInitiative N+1Initiative N+2

Further intitiatives………

Page 37: The CIO's IoT attention points on Enterprise Architecture ... · •IT Risk aspects –the forgotten Challenge? ... Luc Verhelst is an experienced CIO, Digital Consultant and IT Risk

#IoTBuild

Questions?

Thank you